Sr Software Security Architect

Lenovo

Raleigh (NC)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lenovo is seeking a Senior Software Security Architect in the Security Center of Excellence for PC and Smart Devices, based in Morrisville, NC. You will lead a global team of security champions, assess security posture of Lenovo apps for Windows and Android, and help secure preinstalled software across Lenovo devices.

You will guide secure development practices, review architectures, and work with cross-functional teams to address vulnerabilities, ensuring Lenovo’s portfolio remains secure and

Qualifications

  • Bachelor's degree in Computer Science, Computer Engineering, or related field; or relevant cybersecurity experience of 5+ years.
  • 2+ years experience in Computer Security with experience in secure product design, vulnerability management, ethical hacking, and product security testing; 2+ years experience in developing apps for Windows and Android operating systems, using common languages such as C# or Java; Familiarity with security testing tools like Burp Suite, Kali, ZAP.

Responsibilities

  • Lead a global team of development security champions to assess the security posture of Lenovo developed applications for Windows and Android devices.
  • Conduct security assessments of client applications, both Lenovo developed and 3rd party, using industry-standard tools to identify vulnerabilities.
  • Risk-ranking of identified threats to prioritize mitigation and remediation activities.
  • Help train members of development teams in secure development best practices
  • Perform security code reviews of application source code
  • Participate in software design sessions with development teams for secure design and architecture of PC application software
  • Collaborate with development teams to review and address security of Lenovo- and third-party–developed software
  • Act as a trusted advisor on secure application design, development and validation
  • Identify and evaluate needed tools and refine security review processes
  • Define security requirements for Lenovo and third-party development teams
  • Stay current in latest security tools and practices for Windows and mobile app development
  • Act as a Secure Development Lifecycle evangelist within the PCSD group

Skills

Security assessments
Vulnerability management
Secure development
Code reviews
Threat modeling
Windows/Android development
C#
Java
Burp Suite
Kali
OWASP
Reverse engineering

Education

Bachelor's degree in Computer Science/Engineering or related field

Tools

Burp Suite
Kali Linux
OWASP ZAP

Job description

Why Work at Lenovo

Here at Lenovo, we believe in smarter technology for all, so we spend our time building a society that's brighter and more inclusive.

And we go big. No, not big-huge.

We're not just a Fortune 500 company, we're one of Fortune's Most Admired. We're in 180 countries, working with 63,000 brilliant colleagues and counting. And we're known for the world's most complete portfolio of smart technology, from devices to software to infrastructure.

With our ingenuity, we help millions-not just the select few-experience our version of a smarter future.

The one thing that's missing? Well... you...

Description and Requirements
Who You'll Work With

At Lenovo, we manufacture one of the world's widest portfolios of connected products, including PCs (ThinkPad, Yoga, Lenovo Legion), tablets, smartphones, and workstations as well as augmented and virtual reality (Mirage, ThinkReality) and smart home/office solutions. We are also building an innovative portfolio of software and services which are changing the industry. Lenovo is creating the capacity and computing power for the connections that are changing business and society.

About Our Team

This position is for a Senior Software Security Architect in the Security Center of Excellence for PC and Smart Devices business (PCSD). This is an exciting role where you will be working with a global team of development engineers and security professionals - assessing and securing Lenovo applications and devices. You will work with multiple development teams across Lenovo to ensure that secure development practices are followed, as well as working with security champions to review applications that are preinstalled on Lenovo devices. You will be working alongside some of the best security teams in the industry. The security threat landscape presents a wide range of risks to the solutions offered by Lenovo's PC & SD organization - from the Cloud, to PCs, IoT devices, mobile applications and Augmented and Virtual Reality devices. As a Software Security Architect, you will join Lenovo's Global Security Lab, based in Morrisville, NC, as a member of our product security team. This team is responsible for ensuring Lenovo's PC & SD diverse product and technology portfolio is designed, developed and delivered securely for our customers.

What You'll Do
  • Help lead a global team of development security champions to assess the security posture of Lenovo developed applications for Windows and Android devices.
  • Conduct security assessments of client applications, both Lenovo developed and 3rd party, using industry-standard tools and techniques to identify vulnerabilities.
  • Risk-ranking of identified threats to prioritize mitigation and remediation activities.
  • Help train members of development teams in secure development best practices
  • Perform security code reviews of application source code
  • Participate in software design sessions with development teams, analyzing and assisting in the secure design and architecture of PC application software.
  • Working with software designers, developers, project managers, and testers - developing close working partnerships with development teams - to review, assist and recommend changes and solutions to address the security of Lenovo- and third party-developed software
  • Act as a trusted advisor and subject matter expert to product development and engineering teams - provide advice on secure application design, development and validation
  • Identify and evaluate needed tools and refine processes and procedures to ensure security reviews are performed correctly.
  • Define security requirements for Lenovo and third-party development teams.
  • Stay current in the latest security tools, methodologies, and best practices, especially as it relates to Windows and mobile app development.
  • Act as a Secure Development Lifecycle evangelist, guiding and training development teams within the Personal Computer & Smart Devices group on how to effectively and efficiently apply secure development practices
Basic Qualifications:

Bachelor's degree in Computer Science, Computer Engineering, or related field; or relevant cybersecurity experience of 5+ years.

2+ years experience in Computer Security with experience in secure product design, vulnerability management, ethical hacking, and product security testing 2+ years experience in developing apps for Windows and Android operating systems, using common application programming languages such as C# or Java Familiarity with general security testing and reverse engineering tools, such as Burp Suite, Kali, ZAP, etc

Preferred Qualifications:
  • Understanding of general secure development practices: code review, static analysis, OWASP, etc.
  • General knowledge of cryptography concepts such as hash functions and symmetric/asymmetric encryption
  • Knowledge of and experience with applying Common Weakness Enumeration (CWE), Common Vulnerability Scoring System (CVSS), Common Vulnerabilities and Exposures (CVE) and Open Web Application Security Project (OWASP) processes and remediation recommendations.
  • An understanding and ability to communicate the techniques, tactics and practices of an attacker
  • Experience with the application of threat modeling or other risk identification techniques
  • Experience in reverse engineering, disassemblers, debuggers, and developing exploits is a plus.
  • Detailed knowledge of security vulnerabilities and remediation techniques
  • Multiple Industry security certifications such as CISSP, CCSP, SANS-GEVA (or other SANS certs), OCSP
  • Communications skills in Mandarin

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, status as a veteran, and basis of disability or any federal, state, or local protected class.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Manager Software Security
Sr Manager Software Security

Lenovo • Raleigh (NC)

On-site
USD 140,000 - 210,000
Lead Secure Development & Tools Trainer
Lead Secure Development & Tools Trainer

Lenovo • Raleigh (NC)

On-site
USD 110,000 - 140,000
Sr. Product Manager – Platform Security
Sr. Product Manager – Platform Security

Lenovo • Morrisville (NC)

On-site
USD 120,000 - 180,000
Global Software Security Architect - Secure Dev Lifecycle
Global Software Security Architect - Secure Dev Lifecycle

Lenovo • Raleigh (NC)

On-site
USD 140,000 - 190,000
Product Security Engineer – PSIRT
Product Security Engineer – PSIRT

Lenovo • Morrisville (NC)

On-site
USD 120,000 - 150,000
Sr Manager Cloud Security Operations
Sr Manager Cloud Security Operations

Lenovo • Raleigh (NC)

On-site
USD 120,000 - 190,000
Global Software Security Leader (SDLC & App Risk)
Global Software Security Leader (SDLC & App Risk)

Lenovo • Raleigh (NC)

On-site
USD 140,000 - 210,000
Product Security Engineer - PSIRT
Product Security Engineer - PSIRT

Lenovo • Morrisville (NC)

On-site
USD 140,000 - 190,000
Senior Services Sales Executive - Security
Senior Services Sales Executive - Security

Lenovo • North Carolina

Hybrid
USD 215,000 - 230,000
Bonus and/or commission
Comprehensive benefits package
Senior Manager, SW Engineering
Senior Manager, SW Engineering

Lenovo • Morrisville (NC)

On-site
USD 200,000 - 330,000